Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows Explorer restarts and BSOD


  • This topic is locked This topic is locked
44 replies to this topic

#1 PAUL_MARSDEN

PAUL_MARSDEN

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 30 May 2012 - 06:41 PM

Hi,

I'm running Win7 Ultimate on my pc and have started having several different BSOD's and windows explorer restarts. I have recently upgraded the ram to 4gb and put in a new processor. I am thinking that this is an early indication that my main drive is failing (which i have backed up) or i have downloaded a virus or some other nasty!

A sample of the BSOD stop codes i've been generating are below:-

0x0000001A
0x0000007F
0x0000007E

I have carried out a system repair and have disabled various drivers on start up with no improvement.

Any help would be appreciated.

Kind Regards

Paul

Edited by boopme, 01 June 2012 - 03:12 PM.


BC AdBot (Login to Remove)

 


#2 TheShooter93

TheShooter93

    Cody


  • Malware Response Team
  • 4,792 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Orlando, Florida
  • Local time:11:22 AM

Posted 31 May 2012 - 10:45 AM

This does sound hardware related, as those STOP codes are related to hardware issues.

We'll run through some scans, and if nothing turns up we will move the thread into the Hardware section of the forum.

-----------------------------------------------------------

After performing these scans, enter the results in your next post and also update me on the status of the PC.

Note: You may have to perform some or all of the following in Safe Mode With Networking, depending on if you have internet access while in the normal Windows environment. If you still don't have internet access in Safe Mode With Networking, you will need to download the installers onto a flash drive from a working computer and transfer them to the problem PC.

Also, if you have any of the following programs already installed on your machine, download the latest version along with updates, then run the scan.


================================================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

================================================================================

Please download and scan with SUPERAntiSpyware Free
  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
    For instructions with screenshots, please refer to the How to use SUPERAntiSpyware to scan and remove malware from your computer Guide.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all other options as they are set):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the Control Center screen.
  • Back on the main screen, under "Select Scan Type" check the box for Complete Scan.
  • If your computer is badly infected, be sure to check the box next to Enable Rescue Scan (Highly Infected Systems ONLY).
  • Click the Scan your computer... button.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the scan log after reboot, launch SUPERAntiSpyware again.
  • Click the View Scan Logs button at the bottom.
  • This will open the Scanner Logs Window.
  • Click on the log to highlight it and then click on View Selected Log to open it.
  • Copy and paste the scan log results in your next reply.
-- Some types of malware will disable security tools. If SUPERAntiSpyware will not install, please refer to these instructions for using the SUPERAntiSpyware Installer. If SUPERAntiSpyware is already installed but will not run, then follow the instructions for using RUNSAS.EXE to launch the program.

================================================================================

Please download Malwarebytes Anti-Malware Posted Image and save it to your desktop.
  • Important!! When you save the mbam-setup file, rename it to something random (such as 123abc.exe) before beginning the download.
Malwarebytes may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet and double-click on the renamed file to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • Malwarebytes will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button and continue.
  • If you cannot update Malwarebytes or use the Internet to download any files to the infected computer, manually update the database by following the instructions in FAQ Section A: 4. Issues.
  • Under the Scanner tab, make sure the "Perform Quick Scan" option is selected.
  • Click on the Scan button.
  • When finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box, then click the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked and then click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
  • Exit Malwarebytes when done.
Note: If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.

-- Some types of malware will target Malwarebytes and other security tools to keep them from running properly. If that's the case, go to Start > All Programs > Malwarebytes Anti-Malware folder > Tools > click on Malwarebytes Chameleon and follow the onscreen instructions. The Chameleon folder can be accessed by opening the program folder for Malwarebytes Anti-Malware (normally C:\Program Files\Malwarebytes' Anti-Malware or C:\Program Files (x86)\Malwarebytes' Anti-Malware).

================================================================================

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
-- If you encounter any problems, try running GMER in safe mode.
-- If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.

CCNA R&SCCNA Security | Network+  |  B.S. - Information Technology | Cyber Security Engineer

If I am helping you and have not replied within 48 hours, please send me a private message.

 

 


#3 PAUL_MARSDEN

PAUL_MARSDEN
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 01 June 2012 - 12:07 PM

Hi TheShooter93

Some success, some failure.

GMER couldn't complete - ran in safe mode - crashed, ran in normal mode with devices unticked - crashed. Do I need to try running in Safe mode with devices unticked?

Rest of details are below including BSOD output if helpful.

Security check details

Results of screen317's Security Check version 0.99.41
Windows 7 x86 (UAC is disabled!)
Out of date service pack!!
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Lavasoft Ad-Watch Live! Anti-Virus
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Ad-Aware
SpyHunter
SUPERAntiSpyware Free Edition
Malwarebytes Anti-Malware version 1.61.0.1400
CCleaner
EasyCleaner
Java™ 6 Update 31
Java version out of date!
Adobe Flash Player 11.2.202.235
Adobe Reader 9 Adobe Reader out of date!
Adobe Reader X (10.1.3)
Mozilla Firefox (3.6.23) Firefox out of Date!
Google Chrome 19.0.1084.46
Google Chrome 19.0.1084.52


````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe
Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````



Superanti spyware results

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/31/2012 at 10:46 PM

Application Version : 4.53.1000

Core Rules Database Version : 8206
Trace Rules Database Version: 6018

Scan type : Complete Scan
Total Scan Time : 01:50:50

Memory items scanned : 428
Memory threats detected : 0
Registry items scanned : 9997
Registry threats detected : 0
File items scanned : 257478
File threats detected : 519

Adware.Tracking Cookie
C:\Users\a\AppData\Roaming\Microsoft\Windows\Cookies\JX9WWNNK.txt
C:\Users\a\AppData\Roaming\Microsoft\Windows\Cookies\JVZU0O87.txt
C:\Users\a\AppData\Roaming\Microsoft\Windows\Cookies\046OPZ6E.txt
ictv-ic-ec.indieclicktv.com [ C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\7VYGBSP4 ]
media.mtvnservices.com [ C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\7VYGBSP4 ]
s0.2mdn.net [ C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\7VYGBSP4 ]
spe.atdmt.com [ C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\7VYGBSP4 ]
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@247realmedia[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@2o7[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@a1.interclick[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ad.yieldmanager[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ad.zanox[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adbrite[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.ad4game[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.al[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.audience2media[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.bighealthtree[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.cleveland[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.financialcontent[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.masslive[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.mlive[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.nj[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.nola[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.oregonlive[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.pennlive[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.syracuse[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.undertone[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ads.videobash[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adserver.adtechus[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adserving.ezanga[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adserving.greenadvertizing[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adserving.versaneeds[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adtech[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adtech[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adultfriendfinder[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@advertise[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@advertise[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@advertising[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adviva[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@adxpose[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@apmebf[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@apmebf[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@at.atwola[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@atdmt[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@atdmt[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@audience2media[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@austrianairlines.122.2o7[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@azjmp[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@bizzclick[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@bizzclick[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@bs.serving-sys[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@burstnet[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@cdn.jemamedia[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@click.blue-square-media[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@click.fastpartner[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@click.xmlmonetize[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@clickbank[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@clicks.searchalltoday[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@clicks.thespecialsearch[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@clicksor[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@clickthrough.kanoodle[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@collective-media[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@content.yieldmanager[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@content.yieldmanager[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@content.yieldmanager[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@content.yieldmanager[5].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@dc.tremormedia[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@dc.tremormedia[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@doubleclick[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@eas.apm.emediate[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@eclickz[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@eu.gomeotrack[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@fastclick[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@fastclick[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@fidelity.rotator.hadj7.adjuggler[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@find.10topsearches[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@findmypast.co[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@findology[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@findology[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@foodstatsservices[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@habitat.solution.weborama[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@hypertracker[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@imrworldwide[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@imrworldwide[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@indieclick[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@interclick[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@internettrafficbuilder[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@invitemedia[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@ipcmedia.122.2o7[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@kontera[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@liveperson[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@liveperson[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@lovefilm.db.advertising[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@media2.legacy[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@media6degrees[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@mediabrandsww[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@mediaplex[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@mediatraffic[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@mm.chitika[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@myroitracking[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@onlineadtracker.co[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@optimize.indieclick[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@overture[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@p216t1s4450660.kronos.bravenetmedia[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@p220t1s4937009.kronos.bravenetmedia[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@p443t1s4673556.kronos.bravenetmedia[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@questionmarket[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@r1-ads.ace.advertising[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@revsci[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@search.amazeclick[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@search.boltfind[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@search.findxml[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@servedby.adxpower[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@server.lon.liveperson[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@serving-sys[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@serving-sys[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@smartadserver[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@specificclick[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@statcounter[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@statse.webtrendslive[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@tacoda.at.atwola[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@tracking.quisma[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@tradedoubler[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@trafficengine[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@trafficmp[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@tribalfusion[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@tribalfusion[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@weborama[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.adtrak[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.bestdatafind[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.burstnet[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.cpcadnet[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.cpcadnet[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.findmypast.co[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.findmypast.co[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.googleadservices[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@www.popuptraffic[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@xm.xtendmedia[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@xml.trafficengine[2].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@xml.trafficengine[3].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@yieldmanager[1].txt
C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\paul-marsden$@zedo[2].txt
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adviva.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.paypal.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adxpose.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.premiumtv.122.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.247realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dmtracker.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xiti.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtechus.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
wmedia.rotator.hadj7.adjuggler.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
eas.apm.emediate.eu [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.overture.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.overture.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.backbeatmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dealtime.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dealtime.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dealtime.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.afe2.specificclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserver1.backbeatmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.amazon-adsystem.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trackalyzer.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.netgear.122.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.amazon-adsystem.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.247realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediamonkey.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediamonkey.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediamonkey.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediamonkey.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.yieldmanager.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.nextag.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.uk.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad-emea.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad-emea.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad-emea.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad-emea.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.staticwhich.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
tracking.dc-storm.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
7.rotator.wigetmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
7.rotator.wigetmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pagetrackr.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pagetrackr.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.audience2media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.audience2media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
us.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
us.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.unrulymedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.e-2dj6wnmyoldzocp.stats.esomniture.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cbs.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.staticwhich.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.staticwhich.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad-emea.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.e-2dj6wfl4upcpoeo.stats.esomniture.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstbeacon.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstbeacon.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.dealtime.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.stats.paypal.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.estat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.afftracker.info [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.afftracker.info [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickboothlnk.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
publishers.clickbooth.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.sexintheuk.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.sexintheuk.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.sexintheuk.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.sexintheuk.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.sexintheuk.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.ist-track.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.247realmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ox-d.sublimemedia.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mm.chitika.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lucidmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
webstats.plus.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.saymedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickfuse.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
int.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
int.sitestat.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.uk.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickbank.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickbank.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
eas.apm.emediate.eu [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.saymedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.e-2dj6wdkowlazclo.stats.esomniture.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.legitreviews.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.legitreviews.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
tracking.hostgator.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
track.adform.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.myroitracking.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.baa.solution.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.baa.solution.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.baa.solution.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.baa.solution.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.zanox.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xm.xtendmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.harrenmedianetwork.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
optimize.indieclick.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.microsoftsto.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.counter-strike.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adviva.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dennispublishing.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.philips.112.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
wmedia.rotator.hadj7.adjuggler.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.account.driversupport.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.account.driversupport.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserver.zonemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserver.zonemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adfarm1.adition.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adfarm1.adition.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad2.adfarm1.adition.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.advertisespace.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.nextag.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pcstats.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.pcstats.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.pcstats.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
tracking.dc-storm.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.yadro.ru [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.yadro.ru [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.c1.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.c1.atdmt.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.googleads.g.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elites.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elites.co.uk [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
statse.webtrendslive.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.uk.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.uk.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.virginmedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.traveladvertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.traveladvertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.weboramadata.solution.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.weboramadata.solution.weborama.fr [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ar.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.uk.at.atwola.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
click.gamelink.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickfuse.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\a\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
cdnx.tribalfusion.com [ C:\Users\a\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\8TT53AC8 ]
ia.media-imdb.com [ C:\Users\a\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\8TT53AC8 ]


Malware log

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.05.31.07

Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
a :: PAUL-MARSDEN [administrator]

31/05/2012 23:25:40
mbam-log-2012-05-31 (23-25-40).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | PUP | PUM | P2P
Scan options disabled: Heuristics/Shuriken
Objects scanned: 325184
Time elapsed: 7 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

GMER results below




After running security check and clicking on the link to download Antispyware i had a windows desktop manager has stopped (tried to take a screen grab) and then blue screened.

Results of auto restart are here if that helps.

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.1.7600.2.0.0.256.1
Locale ID: 2057

Additional information about the problem:
BCCode: 1a
BCP1: 00000031
BCP2: 88F47EF8
BCP3: 93BBB000
BCP4: BA5BF06D
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1

Files that help describe the problem:
C:\Windows\Minidump\053112-29109-01.dmp
C:\Users\a\AppData\Local\Temp\WER-45879-0.sysdata.xml

Whilst runing gmer had a crash (BSOD)

details are

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.1.7600.2.0.0.256.1
Locale ID: 2057

Additional information about the problem:
BCCode: 1000008e
BCP1: C0000005
BCP2: 83173795
BCP3: B160BADC
BCP4: 00000000
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1

Files that help describe the problem:
C:\Windows\Minidump\060112-33618-01.dmp
C:\Users\a\AppData\Local\Temp\WER-53040-0.sysdata.xml

#4 TheShooter93

TheShooter93

    Cody


  • Malware Response Team
  • 4,792 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Orlando, Florida
  • Local time:11:22 AM

Posted 01 June 2012 - 02:13 PM

You need to uninstall Lavasoft Ad-Watch Live! Anti-Virus as you already have Microsoft Security Essentials.

Nothing serious showed up in the scans, so this is likely hardware related.

I've asked for this thread to be moved to hardware for further troubleshooting.

CCNA R&SCCNA Security | Network+  |  B.S. - Information Technology | Cyber Security Engineer

If I am helping you and have not replied within 48 hours, please send me a private message.

 

 


#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,430 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:22 AM

Posted 01 June 2012 - 03:12 PM

I've moved this to Internal Hardware as it may be a Memory issue.

Edited by boopme, 01 June 2012 - 03:13 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 AustrAlien

AustrAlien

    Inquisitor


  • Members
  • 6,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cowra NSW Australia
  • Local time:01:22 AM

Posted 01 June 2012 - 07:21 PM

Let's collect some more information: I'll have a look at it and help you try to resolve the problem.

:step1: Please follow the instructions: BSOD Posting Instructions: Windows 7 - Vista

(Note: When you run BSOD_Windows7_Vista_v2.64_jcgriff2_.exe, it will also run autoruns.exe ... and both need to be in the same location!)
... with one exception in the following line:
  • "4. Zip up the entire output folder + PERFMON and attach the zip file to your next post."
The BC forums will allow a total attachment size of only 512 kb (and what you need to attach will exceed this limit). Please upload the zip file to a file sharing website of your choice and and post a link to it in this thread so that we can access your uploaded zip file. I will have a look at the contained information and see if I can shed some light on your BSOD issue.

See the suggestions in the following links for recommendations on file sharing websites:
  • http://lifehacker.com/388284/best-online-file-sharing-services
  • http://www.hongkiat.com/blog/15-great-free-online-file-sharing-alternatives/
  • http://www.smashingapps.com/2008/08/28/5-best-free-file-hosting-services-to-store-your-files.html

:step2: Please Publish a Snapshot using Speccy, and post a link to it in this thread.
  • It is a convenient and accurate way of providing us with details of your computer specifications.

:step3: Please download MiniToolBox, save it to your desktop and run it.
  • Checkmark the following checkboxes:
    • List Installed Programs
  • Click Go.
    When the scan is finished, a text file will open in a Notepad window.
  • Copy the entire contents of the Notepad window, and paste in your reply.
    (Result.txt will be saved in the same directory the tool is run.)

AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#7 PAUL_MARSDEN

PAUL_MARSDEN
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 02 June 2012 - 02:10 PM

Thanks guys.

Reports are below.

Link to rar file http://www.mediafire.com/?3dgt19z03in73mu

Speccy output here http://speccy.piriform.com/results/XjKeKvhoIfdZeXWDMwrB3Lx

Mini tool box report

MiniToolBox by Farbar Version: 14-01-2012
Ran by a (administrator) on 02-06-2012 at 20:09:29
Microsoft Windows 7 Ultimate (X86)
Boot Mode: Normal
***************************************************************************

=========================== Installed Programs ============================

A-PDF Merger 4.1
Acrobat.com (Version: 2.0.0)
Acrobat.com (Version: 2.0.0.0)
Adobe AIR (Version: 2.6.0.19120)
Adobe Flash Player 11 ActiveX (Version: 11.2.202.235)
Adobe Flash Player 11 Plugin (Version: 11.2.202.235)
Adobe Reader X (10.1.3) (Version: 10.1.3)
Adobe Shockwave Player 11.5 (Version: 11.5.9.620)
aioprnt (Version: 5.3.1.0)
aioscnnr (Version: 6.2.3.10)
aioscnnr (Version: 7.3.4.0)
AoA Audio Extractor
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
Application Verifier x86 External Package (Version: 8.37.0)
ASUSUpdate
µTorrent (Version: 1.8.2)
µTorrent (Version: 2.2.1)
BIG-IP Edge Client Components (All Users) (Version: 70.2011.0622.1118)
Bonjour (Version: 3.0.0.10)
BUFFALO TurboUSB for FLASH/HDD
Business Contact Manager for Microsoft Outlook 2010 (Version: 4.0.11308.0)
calibre (Version: 0.8.9)
CCleaner (Version: 3.18)
center (Version: 6.2.5.0)
Cool & Quiet
Copy+
Core Temp 1.0 RC3 (Version: 1.0)
Counter-Strike
Counter-Strike: Condition Zero Deleted Scenes
D-Link D-ViewCam (Version: 3.2.3.11)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Defraggler (Version: 2.09)
DiskAid 5.12 (Version: 5.12)
DivX Converter (Version: 7.1.0)
DivX Plus DirectShow Filters
DivX Setup (Version: 2.6.1.5)
DivX Version Checker (Version: 7.1.0.9)
Driver Detective (Version: 8.1)
Driver Sweeper version 3.2.0 (Version: 3.2.0)
DVD Catalyst 3.82 (Version: 3.82)
DVD Catalyst Boosterpack 2 (Version: 2)
EasyCleaner (Version: 2.0.6.380)
ESET Online Scanner v3
essentials (Version: 6.0.14.0)
FLV Player 1.0.3 (Version: 1.0.3)
FlvRipper
Football Manager 2010 (Version: 10.0.1.0)
Google Chrome (Version: 19.0.1084.52)
Google Earth (Version: 6.1.0.5001)
Google Update Helper (Version: 1.3.21.111)
Honda ESM
iCopyExpert 3.1.2
iPhone Configuration Utility (Version: 2.1.0.163)
IrfanView (remove only) (Version: 4.28)
iTunes (Version: 10.6.1.7)
Java Auto Updater (Version: 2.0.7.1)
Java™ 6 Update 31 (Version: 6.0.310)
K-Lite Codec Pack 7.1.0 (Standard) (Version: 7.1.0)
Kits Configuration Installer (Version: 8.37.0)
Kodak AIO Printer (Version: 7.4.0.0)
KODAK AiO Software (Version: 7.4.5.40)
Malwarebytes Anti-Malware version 1.61.0.1400 (Version: 1.61.0.1400)
MAME Classic
MediaMonkey 4.0 (Version: 4.0)
MediaMonkey AAC Plug-in 1.0 (Version: 1.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (Version: 3.5.30730.0)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Security Client (Version: 4.0.1526.0)
Microsoft Security Essentials (Version: 4.0.1526.0)
Microsoft Silverlight (Version: 5.1.10411.0)
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0)
Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Setup Support Files (Version: 10.3.5500.0)
Microsoft SQL Server VSS Writer (Version: 10.3.5500.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.58299)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft® Office Language Pack 2010 – English (Business Contact Manager for Microsoft Outlook 2010) (Version: 4.0.11308.0)
Minilyrics(remove only)
MKVtoolnix 4.5.0 (Version: 4.5.0)
Mozilla Firefox (3.6.23) (Version: 3.6.23 (en-GB))
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MusicBrainz Picard (Version: 0.12.1)
NEC Electronics USB 3.0 Host Controller Driver (Version: 1.0.17.0)
NVIDIA 3D Vision Controller Driver 301.42 (Version: 301.42)
NVIDIA 3D Vision Driver 301.42 (Version: 301.42)
NVIDIA Control Panel 301.42 (Version: 301.42)
NVIDIA Display Control Panel (Version: 6.14.11.9713)
NVIDIA Drivers (Version: 1.10.62.40)
NVIDIA Graphics Driver 301.42 (Version: 301.42)
NVIDIA Install Application (Version: 2.1002.75.420)
NVIDIA PhysX (Version: 9.12.0213)
NVIDIA PhysX System Software 9.12.0213 (Version: 9.12.0213)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.0142)
NVIDIA Update 1.8.15 (Version: 1.8.15)
NVIDIA Update Components (Version: 1.8.15)
ocr (Version: 6.2.3.50)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0)
OutlookTools 2 (Version: 2.3.0)
PC Pitstop Driver Alert2 2.0.0.0 (Version: 2.0.0.0)
PDF to ePUB/Mobi Converter version 2.1 (Version: 2.1)
PeerBlock 1.1 (r518) (Version: 1.1.0.518)
Playlist Creator 3.6.2 (Version: 3.6.2.0)
Plusnet Assist
PreReq (Version: 6.2.3.0)
PunkBuster Services (Version: 0.986)
PVSonyDll (Version: 1.00.0001)
QMC
QuickTime (Version: 7.70.80.34)
RAIDar 4.3.0 (Version: 4.3.0)
ReadyDriver Plus 1.1
RealPlayer
Realtek Ethernet Controller Driver (Version: 7.50.1123.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.6526)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.28.0)
SDK Debuggers (Version: 8.37.0)
SeaTools for Windows (Version: 1.2.0.6)
Service Pack 3 for SQL Server 2008 (KB2546951) (Version: 10.3.5500.0)
Sky Player Desktop
Skype Toolbars (Version: 5.5.7896)
Skype™ 5.3 (Version: 5.3.120)
SMA USB Bus Direct Driver
Speccy (Version: 1.16)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
SpyHunter (Version: 3.10)
Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0)
Steam (Version: 1.0.0.0)
Sunny Explorer (Version: 1.3.4)
SUPER © Version 2010.bld.37 (Jan 2, 2010) (Version: Version 2010.bld.37 (Jan 2, 2010))
SUPERAntiSpyware (Version: 5.0.1150)
System Requirements Lab
TomTom HOME 2.7.6.2056 (Version: 2.7.6.2056)
TomTom HOME Visual Studio Merge Modules (Version: 1.0.2)
TVersity Codec Pack 1.7 (Version: 1.7)
TVersity Media Server 1.9.6 (Version: 1.9.6)
TVersity Media Server Pro 1.9.7 (Version: 1.9.7)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
Veetle TV (Version: 0.9.18)
Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01)
VLC media player 2.0.1 (Version: 2.0.1)
Windows App Certification Kit (Version: 8.37.0)
Windows Installer Clean Up (Version: 3.00.00.0000)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
Windows Software Development Kit (Version: 8.37.0)
Windows Software Development Kit DirectX x86 Remote (Version: 8.37.0)
Windows Software Development Kit for Metro style Apps (Version: 8.37.0)
Windows Software Development Kit for Metro style Apps DirectX x86 Remote (Version: 8.37.0)
Windows Software Development Kit Redistributables (Version: 8.37.0)
WinPcap 4.1.1 (Version: 4.1.0.1753)
WinRAR 4.11 (32-bit) (Version: 4.11.0)
Wondershare Video Converter Ultimate(Build 5.7.1.1)
WPT Redistributables (Version: 8.37.0)
WPTx86 (Version: 8.37.0)
Xilisoft Video Converter Ultimate (Version: 7.0.1.1219)
Xiph.Org Open Codecs 0.85.17777 (Version: 0.85.17777)
XTVFS Read Only File System

**** End of log ****



Paul

#8 AustrAlien

AustrAlien

    Inquisitor


  • Members
  • 6,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cowra NSW Australia
  • Local time:01:22 AM

Posted 03 June 2012 - 07:34 PM

This is a fresh installation of Windows 7, not updated with Service Pack 1 yet.

MS Windows 7 Ultimate 32-bit
Installation Date: 30 May 2012


Why have you chosen to install the 32 bit version of Win7 instead of the 64 bit version?

It is possible that old out-dated drivers belonging to Asus software are causing your BSOD problem:

ASACPI.sys Wed Oct 18 16:44:46 2006
AsIO.sys Mon Dec 17 20:10:20 2007


ASACPI.sys ... Asus ATK0110 ACPI Utility (a known BSOD maker in Win7). Also a part of the Asus PCProbe and AISuite Utilities
AsIO.sys ... Asus PCProbe Utility
  • Visit the motherboard manufacturer's website and download/install all updated drivers (including the Asus PCProbe Utility/AISuite Utilities).
  • Visit Windows Updates and download/install all available updates including Service Pack 1.
Let us know if you are still having problems after doing that.

There are 21 minidumps available over the past 4 days, none of which are proving overly helpful in determining the exact cause of the system crashing.

========================
BSOD BUGCHECK SUMMARY: the most recent crash
................................................................
Loading Dump File [C:\CactusIsland\PAUL_MARSDEN_BC\Windows7_Vista_jcgriff2\060212-34772-01.dmp]
Built by: 7600.16988.x86fre.win7_gdr.120401-1505
Debug session time: Sun Jun 3 01:20:57.219 2012 (UTC + 10:00)
System Uptime: 0 days 0:01:20.014
PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 00000099, A PTE or PFN is corrupt
Arg2: 000c6797, page frame number
Arg3: 00000000, current page state
Arg4: 000c679f, 0
BUGCHECK_STR: 0x4E_99
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x4E_99_nt!MiBadShareCount+24
Bugcheck code 0000004E
Arguments 00000099 000c6797 00000000 000c679f
BiosVersion = 1402
BiosReleaseDate = 05/13/2010
BaseBoardManufacturer = ASUSTeK Computer INC.
BaseBoardProduct = M3N78-AM
BaseBoardVersion = Rev X.0x
................................................................

Edited by AustrAlien, 03 June 2012 - 07:35 PM.

AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#9 PAUL_MARSDEN

PAUL_MARSDEN
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 04 June 2012 - 04:44 PM

Hi,

Installation date relates a repair install that i carried out in an effort to solve BSOD.

I've tried to install SP1 but each time it fails with error code 8007000D.

I've downloaded all drivers and tried to install the ASACPI one fails to take and i don't have the knowledge to force this update.

Next instalment in the lesson please :)

Paul

#10 PAUL_MARSDEN

PAUL_MARSDEN
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 07 June 2012 - 02:42 PM

Bump

#11 AustrAlien

AustrAlien

    Inquisitor


  • Members
  • 6,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cowra NSW Australia
  • Local time:01:22 AM

Posted 07 June 2012 - 02:44 PM

Thanks for the gentle reminder: I haven't forgotten you though.

Things have been a bit too hectic here for an old fella' and I'm struggling to keep up. I have been working on your problem and will get to posting my findings as soon as I can.

Thank you for your patience.
AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#12 PAUL_MARSDEN

PAUL_MARSDEN
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 14 June 2012 - 07:02 AM

Hi,

Have things quietened down?

#13 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:22 PM

Posted 17 June 2012 - 01:53 AM

Hello Paul,
Because AustrAlien is not feeling well I'll see if I can help you with this issue.

Can you please rerun Minitoolbox, and now check the Event Viewer option and run the scan? Post me the resulting log.

Download BlueScreenView
No installation required.
Double click on BlueScreenView.exe file to run the program.
When scanning is done, go Edit>Select All.
Go File>Save Selected Items, and save the report as BSOD.txt.
Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#14 PAUL_MARSDEN

PAUL_MARSDEN
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:04:22 PM

Posted 20 June 2012 - 04:16 PM

Minitool box results

MiniToolBox by Farbar Version: 14-01-2012
Ran by a (administrator) on 20-06-2012 at 22:16:18
Microsoft Windows 7 Ultimate (X86)
Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/20/2012 10:05:05 PM) (Source: Application Error) (User: )
Description: Faulting application name: MsMpEng.exe, version: 4.0.1526.0, time stamp: 0x4f710236
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0340711e
Faulting process id: 0x3c8
Faulting application start time: 0xMsMpEng.exe0
Faulting application path: MsMpEng.exe1
Faulting module path: MsMpEng.exe2
Report Id: MsMpEng.exe3

Error: (06/20/2012 10:01:54 PM) (Source: Application Error) (User: )
Description: Faulting application name: services.exe, version: 6.1.7600.16385, time stamp: 0x4a5bbf1b
Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp: 0x4ec49caf
Exception code: 0xc0000005
Fault offset: 0x0005b96f
Faulting process id: 0x260
Faulting application start time: 0xservices.exe0
Faulting application path: services.exe1
Faulting module path: services.exe2
Report Id: services.exe3

Error: (06/20/2012 10:00:45 PM) (Source: Application Error) (User: )
Description: Faulting application name: MsMpEng.exe, version: 4.0.1526.0, time stamp: 0x4f710236
Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp: 0x4ec49caf
Exception code: 0xc0000374
Fault offset: 0x000c33bb
Faulting process id: 0x3e0
Faulting application start time: 0xMsMpEng.exe0
Faulting application path: MsMpEng.exe1
Faulting module path: MsMpEng.exe2
Report Id: MsMpEng.exe3

Error: (06/20/2012 09:57:21 PM) (Source: Bonjour Service) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 20 6.139.254.169.in-addr.arpa. PTR Paul-Marsden.local.

Error: (06/20/2012 09:57:21 PM) (Source: Bonjour Service) (User: )
Description: mDNSCoreReceiveResponse: Received from 169.254.139.6:5353 22 6.139.254.169.in-addr.arpa. PTR Paul-Marsden-2.local.

Error: (06/20/2012 09:36:42 PM) (Source: Application Error) (User: )
Description: Faulting application name: iexplore.exe, version: 9.0.8112.16446, time stamp: 0x4fb57c8f
Faulting module name: jscript9.dll, version: 9.0.8112.16446, time stamp: 0x4fb57f7f
Exception code: 0xc0000005
Fault offset: 0x00001c1b
Faulting process id: 0x1a8
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3

Error: (06/20/2012 09:16:28 PM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe_ProfSvc, version: 6.1.7600.16385, time stamp: 0x4a5bc100
Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp: 0x4ec49caf
Exception code: 0xc0000005
Fault offset: 0x00051e86
Faulting process id: 0x4a4
Faulting application start time: 0xsvchost.exe_ProfSvc0
Faulting application path: svchost.exe_ProfSvc1
Faulting module path: svchost.exe_ProfSvc2
Report Id: svchost.exe_ProfSvc3

Error: (06/20/2012 11:12:13 AM) (Source: Application Error) (User: )
Description: Faulting application name: taskhost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc0f9
Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp: 0x4ec49caf
Exception code: 0xc0000005
Fault offset: 0x00052eef
Faulting process id: 0x1d90
Faulting application start time: 0xtaskhost.exe0
Faulting application path: taskhost.exe1
Faulting module path: taskhost.exe2
Report Id: taskhost.exe3

Error: (06/20/2012 00:34:25 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/20/2012 00:34:25 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (06/20/2012 10:05:08 PM) (Source: Service Control Manager) (User: )
Description: The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.

Error: (06/20/2012 10:05:05 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

Feature: %%835

Error Code: 0x80070006

Error description: The handle is invalid.

Reason: %%837

Error: (06/20/2012 10:05:05 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

Feature: %%834

Error Code: 0x80070006

Error description: The handle is invalid.

Reason: %%837

Error: (06/20/2012 10:05:05 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 engine has been terminated due to an unexpected error.

Failure Type: %%830

Exception code: 0xc0000005

Resource: file:C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe

Error: (06/20/2012 10:04:05 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd

Error: (06/20/2012 10:04:00 PM) (Source: Microsoft-Windows-Eventlog) (User: LOCAL SERVICE)
Description: The event logging service encountered an error while initializing publishing resources for channel DebugChannel. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Error: (06/20/2012 10:04:00 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 10:01:37 PM on ?6/?20/?2012 was unexpected.

Error: (06/20/2012 10:00:45 PM) (Source: Service Control Manager) (User: )
Description: The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.

Error: (06/20/2012 10:00:43 PM) (Source: Microsoft Antimalware) (User: )
Description: %%860 engine has been terminated due to an unexpected error.

Failure Type: %%830

Exception code: 0xc0000005

Resource:

Error: (06/20/2012 09:59:53 PM) (Source: BugCheck) (User: )
Description: 0x00000050 (0xe8b19aec, 0x00000001, 0x8bd25e80, 0x00000002)C:\Windows\MEMORY.DMP062012-33821-01


Microsoft Office Sessions:
=========================
Error: (06/20/2012 10:05:05 PM) (Source: Application Error)(User: )
Description: MsMpEng.exe4.0.1526.04f710236unknown0.0.0.000000000c00000050340711e3c801cd4f2836f3a620C:\Program Files\Microsoft Security Client\MsMpEng.exeunknown9b82d7a0-bb1b-11e1-9265-002354c18390

Error: (06/20/2012 10:01:54 PM) (Source: Application Error)(User: )
Description: services.exe6.1.7600.163854a5bbf1bntdll.dll6.1.7600.169154ec49cafc00000050005b96f26001cd4f279dba1020C:\Windows\system32\services.exeC:\Windows\SYSTEM32\ntdll.dll2964c2f0-bb1b-11e1-aa51-002354c18390

Error: (06/20/2012 10:00:45 PM) (Source: Application Error)(User: )
Description: MsMpEng.exe4.0.1526.04f710236ntdll.dll6.1.7600.169154ec49cafc0000374000c33bb3e001cd4f279df7f3e0C:\Program Files\Microsoft Security Client\MsMpEng.exeC:\Windows\SYSTEM32\ntdll.dll00a136f0-bb1b-11e1-aa51-002354c18390

Error: (06/20/2012 09:57:21 PM) (Source: Bonjour Service)(User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 20 6.139.254.169.in-addr.arpa. PTR Paul-Marsden.local.

Error: (06/20/2012 09:57:21 PM) (Source: Bonjour Service)(User: )
Description: mDNSCoreReceiveResponse: Received from 169.254.139.6:5353 22 6.139.254.169.in-addr.arpa. PTR Paul-Marsden-2.local.

Error: (06/20/2012 09:36:42 PM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.164464fb57c8fjscript9.dll9.0.8112.164464fb57f7fc000000500001c1b1a801cd4f2301179db8C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\System32\jscript9.dlla494532c-bb17-11e1-9743-002354c18390

Error: (06/20/2012 09:16:28 PM) (Source: Application Error)(User: )
Description: svchost.exe_ProfSvc6.1.7600.163854a5bc100ntdll.dll6.1.7600.169154ec49cafc000000500051e864a401cd4f217a006e00C:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dlld0f2ab10-bb14-11e1-9743-002354c18390

Error: (06/20/2012 11:12:13 AM) (Source: Application Error)(User: )
Description: taskhost.exe6.1.7600.163854a5bc0f9ntdll.dll6.1.7600.169154ec49cafc000000500052eef1d9001cd4ecce08c6a70C:\Windows\system32\taskhost.exeC:\Windows\SYSTEM32\ntdll.dll6710c910-bac0-11e1-90e8-002354c18390

Error: (06/20/2012 00:34:25 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Windows Kits\8.0\bin\x64\filetypeverifier.exe

Error: (06/20/2012 00:34:25 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Windows Kits\8.0\bin\x64\oleview.exe


**** End of log ****


Blue screen view

==================================================
Dump File : 062012-33821-01.dmp
Crash Time : 20/06/2012 21:59:53
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xe8b19aec
Parameter 2 : 0x00000001
Parameter 3 : 0x8bd25e80
Parameter 4 : 0x00000002
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : fltmgr.sys+1de80
Stack Address 3 : fileinfo.sys+669d
Computer Name :
Full Path : C:\Windows\Minidump\062012-33821-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,248
==================================================

==================================================
Dump File : 062012-29936-01.dmp
Crash Time : 20/06/2012 21:57:25
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc080205e
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+b354a
Stack Address 2 : ntkrnlpa.exe+a52f0
Stack Address 3 : ntkrnlpa.exe+24934e
Computer Name :
Full Path : C:\Windows\Minidump\062012-29936-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 154,624
==================================================

==================================================
Dump File : 062012-30014-01.dmp
Crash Time : 20/06/2012 00:38:36
Bug Check String : BAD_POOL_CALLER
Bug Check Code : 0x000000c2
Parameter 1 : 0x00000099
Parameter 2 : 0xce9f1d28
Parameter 3 : 0x00000000
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+334f03
Stack Address 2 : ntkrnlpa.exe+ef5d3
Stack Address 3 : ntkrnlpa.exe+11f544
Computer Name :
Full Path : C:\Windows\Minidump\062012-30014-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,920
==================================================

==================================================
Dump File : 061912-31403-01.dmp
Crash Time : 19/06/2012 22:44:44
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc08020e4
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+b354a
Stack Address 2 : ntkrnlpa.exe+a7854
Stack Address 3 : ntkrnlpa.exe+27ab76
Computer Name :
Full Path : C:\Windows\Minidump\061912-31403-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,280
==================================================

==================================================
Dump File : 061912-35864-01.dmp
Crash Time : 19/06/2012 15:50:25
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc080215e
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+b354a
Stack Address 2 : ntkrnlpa.exe+a7854
Stack Address 3 : ntkrnlpa.exe+27ab76
Computer Name :
Full Path : C:\Windows\Minidump\061912-35864-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 159,104
==================================================

==================================================
Dump File : 061712-30732-01.dmp
Crash Time : 17/06/2012 01:11:44
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 0xe6e3a1d8
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0x830b3a87
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+4682b
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+4682b
Stack Address 1 : ntkrnlpa.exe+a6a87
Stack Address 2 : ntkrnlpa.exe+27c4aa
Stack Address 3 : ntkrnlpa.exe+221b88
Computer Name :
Full Path : C:\Windows\Minidump\061712-30732-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,880
==================================================

==================================================
Dump File : 061712-29889-01.dmp
Crash Time : 17/06/2012 00:41:53
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xda0708ac
Parameter 2 : 0x00000001
Parameter 3 : 0x8309d70a
Parameter 4 : 0x00000002
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : ntkrnlpa.exe+9670a
Stack Address 3 : discache.sys+37e7
Computer Name :
Full Path : C:\Windows\Minidump\061712-29889-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,008
==================================================

==================================================
Dump File : 061612-36348-01.dmp
Crash Time : 16/06/2012 07:56:06
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc08020d4
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+b354a
Stack Address 2 : ntkrnlpa.exe+a7854
Stack Address 3 : ntkrnlpa.exe+27ab76
Computer Name :
Full Path : C:\Windows\Minidump\061612-36348-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,960
==================================================

==================================================
Dump File : 061512-31184-01.dmp
Crash Time : 15/06/2012 23:06:43
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x83286721
Parameter 3 : 0x99f136ec
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+241721
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+241721
Stack Address 1 : ntkrnlpa.exe+255501
Stack Address 2 : ntkrnlpa.exe+236ee1
Stack Address 3 : ntkrnlpa.exe+22166b
Computer Name :
Full Path : C:\Windows\Minidump\061512-31184-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,880
==================================================

==================================================
Dump File : 061412-28844-01.dmp
Crash Time : 14/06/2012 12:51:17
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xdcfb8e84
Parameter 2 : 0x00000001
Parameter 3 : 0x8bd21e80
Parameter 4 : 0x00000002
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : fltmgr.sys+1de80
Stack Address 3 : fileinfo.sys+669d
Computer Name :
Full Path : C:\Windows\Minidump\061412-28844-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,248
==================================================

==================================================
Dump File : 061412-33368-01.dmp
Crash Time : 14/06/2012 12:48:53
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xed2bbc38
Parameter 2 : 0x00000001
Parameter 3 : 0x9b562a17
Parameter 4 : 0x00000002
Caused By Driver : win32k.sys
Caused By Address : win32k.sys+ba075
File Description : Multi-User Win32 Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : win32k.sys+c2a17
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\061412-33368-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,656
==================================================

==================================================
Dump File : 061312-38485-01.dmp
Crash Time : 13/06/2012 22:03:22
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041201
Parameter 2 : 0xc000b050
Parameter 3 : 0xfff3e847
Parameter 4 : 0x898bed50
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+ac6fc
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+ac6fc
Stack Address 1 : ntkrnlpa.exe+adfb6
Stack Address 2 : ntkrnlpa.exe+a5aa4
Stack Address 3 : ntkrnlpa.exe+279c23
Computer Name :
Full Path : C:\Windows\Minidump\061312-38485-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,456
==================================================

==================================================
Dump File : 061212-34601-01.dmp
Crash Time : 12/06/2012 02:04:25
Bug Check String : NTFS_FILE_SYSTEM
Bug Check Code : 0x00000024
Parameter 1 : 0x001904fb
Parameter 2 : 0x8df73734
Parameter 3 : 0x8df73310
Parameter 4 : 0x8be24891
Caused By Driver : Ntfs.sys
Caused By Address : Ntfs.sys+124ed
File Description : NT File System Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : Ntfs.sys+14251
Stack Address 2 : Ntfs.sys+afc3c
Stack Address 3 : Ntfs.sys+b1801
Computer Name :
Full Path : C:\Windows\Minidump\061212-34601-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,248
==================================================

==================================================
Dump File : 061212-31090-01.dmp
Crash Time : 12/06/2012 01:03:45
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc08020c4
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+a5423
Stack Address 2 : ntkrnlpa.exe+24934e
Stack Address 3 : ntkrnlpa.exe+27d7ff
Computer Name :
Full Path : C:\Windows\Minidump\061212-31090-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 160,344
==================================================

==================================================
Dump File : 060612-30420-01.dmp
Crash Time : 06/06/2012 09:47:30
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc08020d6
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+a5423
Stack Address 2 : ntkrnlpa.exe+24934e
Stack Address 3 : ntkrnlpa.exe+27d7ff
Computer Name :
Full Path : C:\Windows\Minidump\060612-30420-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 154,352
==================================================

==================================================
Dump File : 060612-31590-01.dmp
Crash Time : 06/06/2012 00:44:08
Bug Check String : NTFS_FILE_SYSTEM
Bug Check Code : 0x00000024
Parameter 1 : 0x001904fb
Parameter 2 : 0xa3e63a7c
Parameter 3 : 0xa3e63660
Parameter 4 : 0x8c2b3d71
Caused By Driver : Ntfs.sys
Caused By Address : Ntfs.sys+a8d71
File Description : NT File System Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : Ntfs.sys+14251
Stack Address 2 : Ntfs.sys+1925b
Stack Address 3 : ntkrnlpa.exe+7025e
Computer Name :
Full Path : C:\Windows\Minidump\060612-31590-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,872
==================================================

==================================================
Dump File : 060612-36925-01.dmp
Crash Time : 06/06/2012 00:21:38
Bug Check String : APC_INDEX_MISMATCH
Bug Check Code : 0x00000001
Parameter 1 : 0x8328edbc
Parameter 2 : 0x00000000
Parameter 3 : 0xffff0000
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+437d3
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+437d3
Stack Address 1 :
Stack Address 2 :
Stack Address 3 :
Computer Name :
Full Path : C:\Windows\Minidump\060612-36925-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,128
==================================================

==================================================
Dump File : 060612-32214-01.dmp
Crash Time : 06/06/2012 00:19:19
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc080270e
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+b354a
Stack Address 2 : ntkrnlpa.exe+a7854
Stack Address 3 : ntkrnlpa.exe+27ab76
Computer Name :
Full Path : C:\Windows\Minidump\060612-32214-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,872
==================================================

==================================================
Dump File : 060512-37627-01.dmp
Crash Time : 05/06/2012 23:41:58
Bug Check String : DRIVER_CORRUPTED_EXPOOL
Bug Check Code : 0x000000c5
Parameter 1 : 0x000004c4
Parameter 2 : 0x00000002
Parameter 3 : 0x00000001
Parameter 4 : 0x83129067
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+4682b
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+4682b
Stack Address 1 : ntkrnlpa.exe+120067
Stack Address 2 : ntkrnlpa.exe+2196f2
Stack Address 3 : ntkrnlpa.exe+21313d
Computer Name :
Full Path : C:\Windows\Minidump\060512-37627-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,864
==================================================

==================================================
Dump File : 060512-32276-01.dmp
Crash Time : 05/06/2012 00:10:15
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000002
Parameter 2 : 0x000b7515
Parameter 3 : 0x000d7f9f
Parameter 4 : 0x00000001
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+9a174
Stack Address 2 : ntkrnlpa.exe+61ebb
Stack Address 3 : ntkrnlpa.exe+b69b2
Computer Name :
Full Path : C:\Windows\Minidump\060512-32276-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,872
==================================================

==================================================
Dump File : 060412-34897-01.dmp
Crash Time : 04/06/2012 23:34:14
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000099
Parameter 2 : 0x0007ea6e
Parameter 3 : 0x00000002
Parameter 4 : 0x0007ea6d
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+e986c
Stack Address 2 : ntkrnlpa.exe+a048d
Stack Address 3 : ntkrnlpa.exe+a51e4
Computer Name :
Full Path : C:\Windows\Minidump\060412-34897-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,640
==================================================

==================================================
Dump File : 060412-32370-01.dmp
Crash Time : 04/06/2012 21:24:29
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xcf000060
Parameter 2 : 0x00000000
Parameter 3 : 0x8304104e
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : ntkrnlpa.exe+2a04e
Stack Address 3 : Ntfs.sys+aefa2
Computer Name :
Full Path : C:\Windows\Minidump\060412-32370-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 154,616
==================================================

==================================================
Dump File : 060212-31293-01.dmp
Crash Time : 02/06/2012 19:48:35
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041201
Parameter 2 : 0xc0341980
Parameter 3 : 0x59a36005
Parameter 4 : 0x899b5630
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+ac6fc
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+ac6fc
Stack Address 1 : ntkrnlpa.exe+adfb6
Stack Address 2 : ntkrnlpa.exe+a5a8b
Stack Address 3 : ntkrnlpa.exe+279c23
Computer Name :
Full Path : C:\Windows\Minidump\060212-31293-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 158,400
==================================================

==================================================
Dump File : 060212-33041-01.dmp
Crash Time : 02/06/2012 18:58:05
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000002
Parameter 2 : 0x0003fed8
Parameter 3 : 0x000d7f9f
Parameter 4 : 0x00000001
Caused By Driver : fltmgr.sys
Caused By Address : fltmgr.sys+56ad
File Description : Microsoft Filesystem Filter Manager
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+9a174
Stack Address 2 : ntkrnlpa.exe+9aaff
Stack Address 3 : ntkrnlpa.exe+9c0d7
Computer Name :
Full Path : C:\Windows\Minidump\060212-33041-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,872
==================================================

==================================================
Dump File : 060212-32292-01.dmp
Crash Time : 02/06/2012 18:45:41
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xf0bf4f36
Parameter 2 : 0x00000000
Parameter 3 : 0x8308f7f3
Parameter 4 : 0x00000002
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : ntkrnlpa.exe+3e7f3
Stack Address 3 : fileinfo.sys+6790
Computer Name :
Full Path : C:\Windows\Minidump\060212-32292-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,128
==================================================

==================================================
Dump File : 060212-30732-01.dmp
Crash Time : 02/06/2012 18:43:05
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00000031
Parameter 2 : 0x890efd48
Parameter 3 : 0x8d983000
Parameter 4 : 0xaae91f0d
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+28954a
Stack Address 2 : ntkrnlpa.exe+289696
Stack Address 3 : ntkrnlpa.exe+289490
Computer Name :
Full Path : C:\Windows\Minidump\060212-30732-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,128
==================================================

==================================================
Dump File : 060212-29593-01.dmp
Crash Time : 02/06/2012 18:36:04
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc080214a
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9c69
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9c69
Stack Address 1 : ntkrnlpa.exe+b354a
Stack Address 2 : ntkrnlpa.exe+a7854
Stack Address 3 : ntkrnlpa.exe+27ab76
Computer Name :
Full Path : C:\Windows\Minidump\060212-29593-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,872
==================================================

==================================================
Dump File : 060212-34772-01.dmp
Crash Time : 02/06/2012 16:22:50
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000099
Parameter 2 : 0x000c6797
Parameter 3 : 0x00000000
Parameter 4 : 0x000c679f
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+e986c
Stack Address 2 : ntkrnlpa.exe+265acf
Stack Address 3 : ntkrnlpa.exe+9d8dd
Computer Name :
Full Path : C:\Windows\Minidump\060212-34772-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,128
==================================================

==================================================
Dump File : 060212-34616-01.dmp
Crash Time : 02/06/2012 16:20:22
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xffdc101c
Parameter 2 : 0x00000000
Parameter 3 : 0x8304b70f
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : ntkrnlpa.exe+3a70f
Stack Address 3 : fltmgr.sys+a839
Computer Name :
Full Path : C:\Windows\Minidump\060212-34616-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 157,752
==================================================

==================================================
Dump File : 060112-29702-01.dmp
Crash Time : 01/06/2012 22:13:24
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00008884
Parameter 2 : 0x84ea77f0
Parameter 3 : 0x844f0eac
Parameter 4 : 0x00000502
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+34ece
Stack Address 2 : ntkrnlpa.exe+27364
Stack Address 3 : ntkrnlpa.exe+21c7e3
Computer Name :
Full Path : C:\Windows\Minidump\060112-29702-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,384
==================================================

==================================================
Dump File : 060112-30061-01.dmp
Crash Time : 01/06/2012 18:50:20
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xef94e63c
Parameter 2 : 0x00000001
Parameter 3 : 0x8c130e80
Parameter 4 : 0x00000000
Caused By Driver : atapi.sys
Caused By Address : atapi.sys+32df
File Description : ATAPI IDE Miniport Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : fltmgr.sys+1de80
Stack Address 3 : fileinfo.sys+669d
Computer Name :
Full Path : C:\Windows\Minidump\060112-30061-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,768
==================================================

==================================================
Dump File : 060112-30560-01.dmp
Crash Time : 01/06/2012 12:53:57
Bug Check String : BAD_POOL_HEADER
Bug Check Code : 0x00000019
Parameter 1 : 0x00000003
Parameter 2 : 0x859df480
Parameter 3 : 0x20534654
Parameter 4 : 0x859df480
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+120232
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+120232
Stack Address 1 : ntkrnlpa.exe+27c8de
Stack Address 2 : ntkrnlpa.exe+1f7ee3
Stack Address 3 : dxgkrnl.sys+69de0
Computer Name :
Full Path : C:\Windows\Minidump\060112-30560-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 160,328
==================================================

==================================================
Dump File : 060112-29499-01.dmp
Crash Time : 01/06/2012 02:14:12
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x8255a795
Parameter 3 : 0x8cc2579c
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+120795
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+120795
Stack Address 1 : ntkrnlpa.exe+11f8aa
Stack Address 2 : ntkrnlpa.exe+2391ac
Stack Address 3 : ntkrnlpa.exe+27ec2b
Computer Name :
Full Path : C:\Windows\Minidump\060112-29499-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 139,944
==================================================

==================================================
Dump File : 060112-30045-01.dmp
Crash Time : 01/06/2012 00:45:29
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xb2a00000
Parameter 2 : 0x00000000
Parameter 3 : 0x830457f3
Parameter 4 : 0x00000002
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : ntkrnlpa.exe+3e7f3
Stack Address 3 : ntkrnlpa.exe+27b485
Computer Name :
Full Path : C:\Windows\Minidump\060112-30045-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 160,568
==================================================

==================================================
Dump File : 060112-33618-01.dmp
Crash Time : 01/06/2012 00:17:46
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0x83173795
Parameter 3 : 0xb160badc
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+120795
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+120795
Stack Address 1 : ntkrnlpa.exe+11f8aa
Stack Address 2 : ntkrnlpa.exe+24bd98
Stack Address 3 : ntkrnlpa.exe+275dfe
Computer Name :
Full Path : C:\Windows\Minidump\060112-33618-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 160,568
==================================================

==================================================
Dump File : 053112-29109-01.dmp
Crash Time : 31/05/2012 20:46:53
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00000031
Parameter 2 : 0x88f47ef8
Parameter 3 : 0x93bbb000
Parameter 4 : 0xba5bf06d
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+28954a
Stack Address 2 : ntkrnlpa.exe+289696
Stack Address 3 : ntkrnlpa.exe+289490
Computer Name :
Full Path : C:\Windows\Minidump\053112-29109-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 156,632
==================================================

==================================================
Dump File : 053112-30950-01.dmp
Crash Time : 31/05/2012 01:39:57
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x00000050
Parameter 1 : 0xde9e92e4
Parameter 2 : 0x00000000
Parameter 3 : 0x9b44f33d
Parameter 4 : 0x00000002
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+85a43
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+85a43
Stack Address 1 : ntkrnlpa.exe+46638
Stack Address 2 : win32k.sys+df33d
Stack Address 3 : win32k.sys+de60a
Computer Name :
Full Path : C:\Windows\Minidump\053112-30950-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 154,824
==================================================

==================================================
Dump File : 053112-32526-01.dmp
Crash Time : 31/05/2012 00:30:19
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc080206a
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : halmacpi.dll
Caused By Address : halmacpi.dll+5ba9
File Description : Hardware Abstraction Layer DLL
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+a06fe
Stack Address 1 : ntkrnlpa.exe+a51e4
Stack Address 2 : ntkrnlpa.exe+24934e
Stack Address 3 : ntkrnlpa.exe+27d7ff
Computer Name :
Full Path : C:\Windows\Minidump\053112-32526-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,984
==================================================

==================================================
Dump File : 053012-41028-01.dmp
Crash Time : 30/05/2012 23:45:26
Bug Check String : PFN_LIST_CORRUPT
Bug Check Code : 0x0000004e
Parameter 1 : 0x00000099
Parameter 2 : 0x000ff92f
Parameter 3 : 0x00000005
Parameter 4 : 0x00110025
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+dcea4
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : ntkrnlpa.exe+e986c
Stack Address 2 : ntkrnlpa.exe+a048d
Stack Address 3 : ntkrnlpa.exe+a51e4
Computer Name :
Full Path : C:\Windows\Minidump\053012-41028-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,768
==================================================

==================================================
Dump File : 053012-34460-01.dmp
Crash Time : 30/05/2012 21:30:02
Bug Check String :
Bug Check Code : 0x0000010e
Parameter 1 : 0x0000001f
Parameter 2 : 0xf36e5d58
Parameter 3 : 0x00000000
Parameter 4 : 0x0000293f
Caused By Driver : watchdog.sys
Caused By Address : watchdog.sys+51f0
File Description : Watchdog Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+dcea4
Stack Address 1 : watchdog.sys+1276
Stack Address 2 : dxgmms1.sys+18c6e
Stack Address 3 : dxgmms1.sys+1a9be
Computer Name :
Full Path : C:\Windows\Minidump\053012-34460-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 154,200
==================================================

==================================================
Dump File : 053012-33212-01.dmp
Crash Time : 30/05/2012 19:06:38
Bug Check String : BAD_POOL_HEADER
Bug Check Code : 0x00000019
Parameter 1 : 0x00000020
Parameter 2 : 0xc25ac528
Parameter 3 : 0xc25ace08
Parameter 4 : 0x0b1c0623
Caused By Driver : Lbd.sys
Caused By Address : Lbd.sys+c300
File Description :
Product Name :
Company :
File Version :
Processor : 32-bit
Crash Address : ntkrnlpa.exe+11f1b6
Stack Address 1 : ntkrnlpa.exe+120a76
Stack Address 2 : Lbd.sys+1a28
Stack Address 3 : ntkrnlpa.exe+2807a5
Computer Name :
Full Path : C:\Windows\Minidump\053012-33212-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 153,032
==================================================

==================================================
Dump File : 053012-38563-01.dmp
Crash Time : 30/05/2012 09:41:29
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc08020be
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9b1d
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9b1d
Stack Address 1 : ntkrnlpa.exe+b33fe
Stack Address 2 : ntkrnlpa.exe+a7708
Stack Address 3 : ntkrnlpa.exe+27a4c8
Computer Name :
Full Path : C:\Windows\Minidump\053012-38563-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,128
==================================================

==================================================
Dump File : 053012-27892-01.dmp
Crash Time : 30/05/2012 09:38:26
Bug Check String : BAD_POOL_CALLER
Bug Check Code : 0x000000c2
Parameter 1 : 0x00000007
Parameter 2 : 0x00001097
Parameter 3 : 0x310b052a
Parameter 4 : 0xcec9d958
Caused By Driver : halmacpi.dll
Caused By Address : halmacpi.dll+3900
File Description : Hardware Abstraction Layer DLL
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+11f1b6
Stack Address 1 : Ntfs.sys+9920c
Stack Address 2 : Ntfs.sys+92541
Stack Address 3 : Ntfs.sys+b14c3
Computer Name :
Full Path : C:\Windows\Minidump\053012-27892-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 151,872
==================================================

==================================================
Dump File : 053012-34491-01.dmp
Crash Time : 30/05/2012 09:13:38
Bug Check String : MEMORY_MANAGEMENT
Bug Check Code : 0x0000001a
Parameter 1 : 0x00041790
Parameter 2 : 0xc08027a8
Parameter 3 : 0x0000ffff
Parameter 4 : 0x00000000
Caused By Driver : ntkrnlpa.exe
Caused By Address : ntkrnlpa.exe+b9b1d
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16988 (win7_gdr.120401-1505)
Processor : 32-bit
Crash Address : ntkrnlpa.exe+b9b1d
Stack Address 1 : ntkrnlpa.exe+b33fe
Stack Address 2 : ntkrnlpa.exe+a7708
Stack Address 3 : ntkrnlpa.exe+27a4c8
Computer Name :
Full Path : C:\Windows\Minidump\053012-34491-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 152,560
==================================================

Regards

Paul

#15 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:22 PM

Posted 21 June 2012 - 11:39 AM

Please click Start > All Programs > Accessories, right click Command Prompt and select "run as administrator".

Type chkdsk /r and press enter.
When asked if you want to schedule a disk check, confirm. Restart your computer and let the disk check unhindered. Note, this may take some time.

After doing this, if the problems remain, restart the computer and tap F10 until the Edit Boot Menu screen comes up. Press tab to select Windows Memory Diagnostics. Press enter and carry out the diagnostic, let me know if anything is found.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users